Ok.. I ran ComboFix again.. This time I got a log in the end..
Here's the log:
ComboFix 10-07-05.03 - Admin 07/06/2010 11:08:52.1.1 - x86
MicrosoftŽ Windows Vista Home Premium 6.0.6002.2.1252.1.1033.18.894.420 [GMT -4:00]
Running from: c:\users\Admin\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Mozilla Firefox\extensions\{6F8D8CD1-C3CA-4532-878B-35C0B6FC318C}
c:\program files\Mozilla Firefox\extensions\{6F8D8CD1-C3CA-4532-878B-35C0B6FC318C}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{6F8D8CD1-C3CA-4532-878B-35C0B6FC318C}\chrome\content\overlay.xul
c:\program files\Mozilla Firefox\extensions\{6F8D8CD1-C3CA-4532-878B-35C0B6FC318C}\install.rdf
c:\programdata\Microsoft\Windows\Start Menu\Programs\Antimalware Doctor
c:\programdata\Microsoft\Windows\Start Menu\Programs\Antimalware Doctor\Antimalware Doctor.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\Antimalware Doctor\Uninstall.lnk
c:\recycler\k-1-3542-4232123213-7676767-8888886
c:\users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Antimalware Doctor.lnk
c:\users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antimalware Doctor
c:\users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Antimalware Doctor.lnk
c:\users\Admin\Desktop\Antimalware Doctor.lnk
c:\users\Alo&Ann\ComboFix.exe
c:\users\Alo&Ann\Desktop\Antimalware Doctor.lnk
c:\users\ELLAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Security Tool.lnk
c:\users\ELLAN\Desktop\Security Tool.lnk
c:\users\Guest\Desktop\Antimalware Doctor.lnk
c:\users\Pauline\Desktop\Antimalware Doctor.lnk
c:\users\Quinito\Desktop\Antimalware Doctor.lnk
c:\windows\system32\ahtn.htm
c:\windows\system32\lmppcsetup.exe
c:\windows\system32\ovfsthxityjmewp.dat
c:\windows\system32\ovfsthxjebfxyxx.dat
c:\windows\system32\p2hhr.bat
c:\windows\system32\warning.gif
c:\windows\system32\win32hlp.cnf
.
((((((((((((((((((((((((( Files Created from 2010-06-06 to 2010-07-06 )))))))))))))))))))))))))))))))
.
2010-07-06 15:19 . 2010-07-06 15:20 -------- d-----w- c:\users\Admin\AppData\Local\temp
2010-07-06 15:19 . 2010-07-06 15:19 -------- d-----w- c:\users\Quinito\AppData\Local\temp
2010-07-06 15:19 . 2010-07-06 15:19 -------- d-----w- c:\users\Pauline\AppData\Local\temp
2010-07-06 15:19 . 2010-07-06 15:19 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-07-06 15:19 . 2010-07-06 15:19 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-07-06 15:19 . 2010-07-06 15:19 -------- d-----w- c:\users\Alo&Ann\AppData\Local\temp
2010-07-06 15:19 . 2010-07-06 15:19 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2010-07-06 11:30 . 2010-07-06 11:30 -------- d-----w- c:\programdata\Office Genuine Advantage
2010-07-06 03:14 . 2010-07-06 03:14 -------- d-----w- c:\users\Guest\AppData\Roaming\vlc
2010-07-06 03:02 . 2010-07-06 03:05 -------- d-----w- c:\users\Guest\AppData\Local\Adobe
2010-07-05 10:26 . 2010-07-05 10:26 981780 ----a-w- c:\users\Alo&Ann\tdsskiller.zip
2010-07-03 00:54 . 2010-07-06 06:18 -------- d-----w- C:\D987BE45BE96B441BBEB7498D358C05E
2010-06-24 18:34 . 2010-06-24 18:34 46852 ----a-w- c:\programdata\Blizzard Entertainment\Battle.net\Cache\Download\Scan.dll
2010-06-23 07:02 . 2009-11-08 14:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-23 07:02 . 2009-11-08 14:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-23 07:02 . 2009-11-08 14:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-23 07:02 . 2009-11-08 14:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-23 07:02 . 2009-11-08 14:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-06-22 17:09 . 2010-04-16 16:43 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-06-22 17:09 . 2010-04-16 14:39 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-06-19 22:20 . 2010-06-17 18:35 43008 ----a-w- c:\users\Alo&Ann\AppData\Roaming\Mozilla\Firefox\Profiles\iur257md.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2010-06-19 22:20 . 2010-06-17 18:35 339456 ----a-w- c:\users\Alo&Ann\AppData\Roaming\Mozilla\Firefox\Profiles\iur257md.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2010-06-19 22:20 . 2010-06-17 18:35 346112 ----a-w- c:\users\Alo&Ann\AppData\Roaming\Mozilla\Firefox\Profiles\iur257md.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2010-06-19 22:20 . 2010-06-17 18:35 1496064 ----a-w- c:\users\Alo&Ann\AppData\Roaming\Mozilla\Firefox\Profiles\iur257md.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2010-06-16 21:40 . 2010-06-16 21:40 -------- d--h--r- c:\users\Alo&Ann\AppData\Roaming\SecuROM
2010-06-15 02:55 . 2010-03-26 14:33 1496064 ----a-w- c:\users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\l6tcyn0g.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2010-06-15 02:55 . 2010-03-26 14:33 43008 ----a-w- c:\users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\l6tcyn0g.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2010-06-15 02:55 . 2010-03-26 14:33 339456 ----a-w- c:\users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\l6tcyn0g.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2010-06-15 02:55 . 2010-03-26 14:32 346112 ----a-w- c:\users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\l6tcyn0g.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2010-06-14 21:33 . 2010-06-14 21:33 -------- d--h--r- c:\users\Guest\AppData\Roaming\SecuROM
2010-06-09 22:56 . 2010-04-05 17:01 67072 ----a-w- c:\windows\system32\asycfilt.dll
2010-06-09 22:56 . 2010-05-26 14:47 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-06-09 22:56 . 2010-05-26 17:06 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-06-09 22:52 . 2010-05-01 14:13 2037248 ----a-w- c:\windows\system32\win32k.sys
2010-06-06 18:47 . 2010-06-06 18:47 -------- d-----w- c:\users\Alo&Ann\AppData\Local\Blizzard Entertainment
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-06 00:52 . 2009-02-12 00:06 -------- d-----w- c:\programdata\Google Updater
2010-06-28 13:19 . 2009-10-10 20:27 107352 ----a-w- c:\users\Alo&Ann\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-25 07:03 . 2009-01-05 00:43 -------- d-----w- c:\program files\Microsoft.NET
2010-06-14 21:43 . 2009-04-16 23:35 107352 ----a-w- c:\users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-10 16:16 . 2009-04-26 04:42 107352 ----a-w- c:\users\Admin\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-10 07:55 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-06-08 08:49 . 2010-06-06 08:42 -------- d-----w- c:\program files\StarCraft II Beta
2010-06-06 21:24 . 2010-06-06 08:42 -------- d-----w- c:\programdata\Blizzard Entertainment
2010-06-06 08:49 . 2010-06-06 08:42 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-06-06 08:39 . 2010-06-06 08:39 -------- d-----w- c:\programdata\Blizzard
2010-06-05 21:49 . 2009-12-05 14:50 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-03 02:41 . 2010-06-03 02:41 3600384 ----a-w- c:\windows\system32\GPhotos.scr
2010-05-31 03:02 . 2010-05-31 03:02 50354 ----a-w- c:\users\Pauline\AppData\Roaming\Facebook\uninstall.exe
2010-05-31 03:02 . 2010-05-31 03:02 -------- d-----w- c:\users\Pauline\AppData\Roaming\Facebook
2010-05-30 18:29 . 2009-02-11 16:20 107352 ----a-w- c:\users\Pauline\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-28 19:54 . 2008-07-30 14:34 -------- d-----w- c:\program files\Yahoo!
2010-05-28 13:23 . 2008-07-30 14:29 -------- d-----w- c:\programdata\WildTangent
2010-05-16 04:06 . 2009-02-12 00:06 -------- d-----w- c:\program files\Google
2010-05-04 05:59 . 2010-06-09 22:55 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 05:55 . 2010-06-09 22:55 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-05-04 05:55 . 2010-06-09 22:55 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-05-04 04:31 . 2010-06-09 22:55 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-04-23 14:13 . 2010-05-26 00:55 2048 ----a-w- c:\windows\system32\tzres.dll
2010-04-23 14:10 . 2010-04-23 14:10 690952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-04-16 16:43 . 2010-06-22 17:09 173056 ----a-w- c:\windows\AppPatch\AcXtrnal.dll
2010-04-16 16:43 . 2010-06-22 17:09 458752 ----a-w- c:\windows\AppPatch\AcSpecfc.dll
2010-04-16 16:43 . 2010-06-22 17:09 542720 ----a-w- c:\windows\AppPatch\AcLayers.dll
2010-04-16 16:43 . 2010-06-22 17:09 2159616 ----a-w- c:\windows\AppPatch\AcGenral.dll
2009-04-01 02:47 . 2009-01-02 03:43 324976 ----a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
2008-08-16 22:42 . 2008-08-16 22:42 13112 ----a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2008-08-16 22:42 . 2008-08-16 22:42 70456 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2008-08-16 22:42 . 2008-08-16 22:42 91448 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2008-08-16 22:42 . 2008-08-16 22:42 20800 ----a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2008-08-16 22:43 . 2008-08-16 22:43 206136 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2008-08-16 22:42 . 2008-08-16 22:42 31032 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2008-08-16 22:42 . 2008-08-16 22:42 40248 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2008-05-21 13:41 . 2008-05-21 13:41 479232 ----a-w- c:\program files\mozilla firefox\plugins\msvcm80.dll
2008-05-21 13:41 . 2008-05-21 13:41 548864 ----a-w- c:\program files\mozilla firefox\plugins\msvcp80.dll
2008-05-21 13:41 . 2008-05-21 13:41 626688 ----a-w- c:\program files\mozilla firefox\plugins\msvcr80.dll
2008-06-05 18:58 . 2008-06-05 18:58 648504 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2008-08-16 22:42 . 2008-08-16 22:42 23864 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
2008-07-30 14:43 . 2008-07-30 14:43 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2010-01-08 2935480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-22 92704]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-22 13539872]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2008-01-21 215552]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"RDFNSListener"="c:\program files\RegDefense\RDFNSListener.exe" [2009-11-18 106608]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Citrix XenApp.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Citrix XenApp.lnk
backup=c:\windows\pss\Citrix XenApp.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PictureMover.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\PictureMover.lnk
backup=c:\windows\pss\PictureMover.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 06:04 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlackBerryAutoUpdate]
2008-09-19 20:06 615696 ----a-w- c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2007-04-04 01:50 1603152 ----a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2007-05-15 01:01 644696 ----a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
2008-06-02 22:14 75008 ----a-w- c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 23:24 54840 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPADVISOR]
2008-07-03 19:44 972080 ----a-w- c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
2007-04-18 15:01 65536 ----a-w- c:\hp\support\hpsysdrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPInSightLAN 01]
2005-08-11 02:10 380928 ----a-w- c:\program files\EarthLink TotalAccess\FastLane2\IPClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPInSightMonitor 01]
2005-08-11 02:10 122880 ----a-w- c:\program files\EarthLink TotalAccess\FastLane2\ipmon32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
2008-08-14 22:11 565008 ----a-w- c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2008-08-14 22:15 2407184 ----a-w- c:\program files\Logitech\QuickCam\Quickcam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
2007-02-04 17:02 79400 ----a-w- c:\program files\ScanSoft\OmniPageSE4\OpWareSE4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
2008-08-26 17:23 236016 ----a-w- c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2006-10-25 14:03 210472 ----a-w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-04-07 09:56 132760 ----a-w- c:\program files\Java\jre1.6.0_01\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WrtMon.exe]
2006-09-20 13:35 20480 ----a-w- c:\windows\System32\spool\drivers\w32x86\3\WrtMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(

:01,f0,5d,4b,bb,49,ca,01
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate1c98ca5efdc6a30;Google Update Service (gupdate1c98ca5efdc6a30);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-12 133104]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0308000.029\SYMEFA.SYS [2009-08-22 310320]
S1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\Drivers\N360\0308000.029\BHDrvx86.sys [2009-08-22 259632]
S1 ccHP;Symantec Hash Provider;c:\windows\System32\Drivers\N360\0308000.029\ccHPx86.sys [2009-08-22 482432]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20100706.002\IDSvix86.sys [2010-05-28 344112]
S2 N360;Norton 360;c:\program files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe [2009-08-22 117640]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-05-26 102448]
S3 HSXHWBS3;HSXHWBS3;c:\windows\system32\DRIVERS\HSXHWBS3.sys [2008-02-12 207360]
S3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS [2009-08-22 48688]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 11:32 128512 ----a-w- c:\windows\System32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
2010-07-06 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-12 17:13]
2010-07-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-12 00:07]
2010-07-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-12 00:07]
2010-07-04 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2008-02-22 16:25]
2010-07-03 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2008-02-22 16:25]
2010-07-06 c:\windows\Tasks\User_Feed_Synchronization-{7172AFFB-2B34-47FF-8A06-3B238BD1E0A7}.job
- c:\windows\system32\msfeedssync.exe [2010-06-09 04:30]
2010-07-06 c:\windows\Tasks\User_Feed_Synchronization-{76F357C0-E099-497C-B85E-83123E80A3C1}.job
- c:\windows\system32\msfeedssync.exe [2010-06-09 04:30]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-Framework Windows - frmwrk32.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-07-06 11:20
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
ßĘDØYßÉ DØZ [-2134240801] 0x006F0063
ßĘDØYßÉ DØZ [-2134240801] 0x00700069
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.8.0.41\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-07-06 11:25:51
ComboFix-quarantined-files.txt 2010-07-06 15:25
Pre-Run: 103,150,460,928 bytes free
Post-Run: 108,887,752,704 bytes free
- - End Of File - - E5CF41EB2E502D9D4FCED187413BA7DD
Overall there seems to be no attacks being detected by Norton.. But I feel that the computer is still working slower than usual.